Privacy

This notice explains what rent.fyi processes when you use the public tools, contribute a rent, or choose to create an account.

Addresses and rent contributions

When you add your rent, we collect the full property address, full postcode, monthly rent, property size, address source and submission time. The address helps us build building-level statistics, understand changes over time, and match EPC-derived property data. We never collect your name. This includes names, avatars and other profile fields returned by Google OAuth.

Addresses and individual rents are never displayed, shared, sold or included in an API response, share link or OG image. Public results are aggregates only. A contribution is stored in the separate rent_submissions store and is never linked to an account, profile or contact row. This means an account cannot be used to find or delete a contribution; use its one-time receipt reference instead.

Optional accounts

You can use rent check, every static rent page, true cost, comparison, sharing and all trust pages without signing in. An optional account uses Supabase Auth. Magic-link email is the primary method; Google OAuth is a secondary option. Supabase receives the email needed to authenticate you. Google receives the authentication request and may process it across its service regions; we keep only the email, never the Google display name, avatar or locale.

The strictly necessary session cookie is named rent-fyi-auth. It keeps your login active and is not used for analytics or advertising. Signed-in users can save rent checks and comparisons, opt in to a separate rent-history copy and manage renewal alerts. The history copy is not a link to the contribution.

Other browser and service data

Comparisons, saved rent checks and the local commute convenience profile stay in your browser unless you explicitly save them to your account. EPC addresses are queried on demand; only derived figures are cached under a salted address hash. Exploratory searches save only an outcode, property size, coarse rent band and time. They do not save a full postcode, exact rent or address.

Plausible Analytics is cookieless and receives page views plus a fixed set of product events. It receives no address, postcode, rent amount, building name or user property. Sentry receives application errors with replay disabled and PII scrubbing; postcode, address and money values are scrubbed before transmission.

Lawful basis, retention and providers

The final lawful bases, retention periods and international-transfer wording require professional review. Current engineering intent is consent or another reviewed basis for voluntary contributions, service necessity for requested lookups, and carefully balanced legitimate interests for security and low-data measurement. Rent contributions and search telemetry currently have no automatic deletion period; this is a launch decision. Rate-limit rows expire within 24 hours and the EPC derived cache expires after 30 days.

Providers are Netlify for hosting (service region to be confirmed), Supabase (EU production region to be confirmed), the UK EPC Register, Cloudflare Turnstile, Plausible (EU-hosted), Sentry (EU/DE project) and Google for optional OAuth. Their DPAs, subprocessors and transfer mechanisms must be recorded before launch.

Removing data

A contribution confirmation shows a reference such as RF-7K2M-9XQ4 once. We store only a salted hash. Use Remove my rent record; a lost reference cannot be recovered. You can also email the support address shown on How estimates work with the address, rent and approximate submission date so we can review an erasure request.

Deleting an account removes its profile, saved rent checks, saved comparisons, rent-history copies and contact rows. It does not remove contributions, which were never linked to that account.